formance

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s actions match its stated purpose, and the CLI install path is an official npm package rather than an opaque binary. However, the core integration is not direct Formance access: authentication, connections, and action execution are mediated by Membrane, so Formance data and auth context flow through a third-party broker. That mismatch raises medium security risk even without clear malicious behavior.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fformance%2F@e5eda8c532c8194e4700139c83048bedfbcc2597
Security Audit — socket — formance